The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as…
WPScan·CWE-79·Published 2022-01-24